Lune

CRYPTO2026Top-tier venue

Classical and Quantum Full Plaintext Recovery for Low-Round Feistel-Type Designs

Tingting Guo, Peng Wang, Jiwu Jing, Shuping Mao, Gang Liu

2026Year

Abstract

The Feistel (Luby-Rackoff) structure underlies numerous block-cipher and mode-of-operation designs, whose security is traditionally assessed via indistinguishability. For low-round Feistel constructions, a variety of classical and quantum distinguishing attacks are known. In this work, we show that such distinguishing attacks can be systematically upgraded to full plaintext recovery with essentially the same query complexity. We establish classical recovery attacks on the 22-round Feistel under CPA and the 33-round Feistel under CCA using only three queries, and introduce quantum-assisted forward/backward extension techniques based on Simon’s algorithm that yield recovery attacks on the 33-round Feistel under qCPA and the 44-round Feistel under qCCA. We further prove that the attacks extend to the Unified Feistel-Lai-Massey (UFLM) framework and therefore apply to a broad class of two-branch constructions. As a consequence, we obtain plaintext-recovery attacks on 4/5/64/5/6-round Feistel-FK and on several practical enciphering schemes, including AEZ-core, FMix, OleF, double-decker, and docked-double-decker. Overall, our results reveal a fundamental connection between distinguishing and full plaintext recovery in low-round two-branch Feistel-type designs, in both classical and quantum settings.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get ec7de014-7997-4495-941b-7fbf8f97310e

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines